Release Note
Last verified 29 Sep 2026
Isolated Worker Nodes for DigitalOcean Kubernetes (DOKS) are now in general availability. Every worker node in an isolated cluster runs without a public IPv4 address, so nodes are removed from the public internet at the network level rather than only protected by a firewall.
Outbound traffic, including node provisioning and container image pulls, routes through a VPC NAT Gateway, and other resources in the same VPC reach the nodes over private addresses. The Kubernetes API server stays publicly reachable so you can still manage the cluster. You can enable isolation only when you create a cluster running Kubernetes 1.36 or later.